Find the Right GRC Solution

Search and compare GRC technology built for the problems you’re trying to solve

Insights

When Controls Compete With Each Other

A critical system goes down, and the operations team needs an administrator inside it immediately. Privileged access, however, requires approval, and the designated approver is unavailable. A change may restore the system, but normal procedure requires testing before anything reaches production. Meanwhile, the recovery clock is running.

The Compliance Illusion: When More Controls Create More Risk

There is a strange rule in compliance: when something goes wrong, organizations add a control. A regulator raises a concern? Add a control. An auditor finds a weakness? Add another. A cyberattack happens? Add three. A new framework arrives? Someone opens a spreadsheet. Nobody ever gets celebrated for deleting one.

Governing AI Between the Checkpoints

A few weeks ago, I wrote about a question that had followed me from a computer room in Milwaukee thirty years ago into today's conversations about agentic AI, "Where is the big red button?"

When Seeing Is No Longer Believing: Deepfakes Are Becoming a Governance Problem

For a long time, seeing someone or hearing their voice gave us a reasonable level of confidence that we knew who we were dealing with. If your manager called, you recognized their voice. If a senior executive joined a video meeting, you could see them on the screen. There was usually little reason to question whether the person you were speaking to was actually who they claimed to be.

The “AI Employee” Is a Governance Failure Waiting to Happen

Corporate America has found a new way to signal its ambition: hiring software. Companies are giving artificial intelligence (AI) agents names, titles, and places on the organizational chart, and press releases celebrate the arrival of the “first AI employee” as though a person had walked through the door. According to MIT Technology Review’s James O’Donnell, nearly a third of the 1,261 managers surveyed in a recent Boston University study said their companies already frame AI agents as employees, and 23 percent list them on org charts.

The Strange Afterlife of a Regulation

Article 30 of the GDPR requires organizations to maintain a record of processing activities, a running account of what personal data is collected, why, where it goes, and how long it is kept. In the spring of 2018, producing this record was urgent work, done under outside counsel's supervision and briefed to the board. Seven years on, in a great many organizations, it is a spreadsheet that gets copied forward each quarter by whoever currently holds the job, edited just enough to survive an audit, verified by almost no one, because verifying it would mean re-establishing, line by line, whether the data flows it describes still exist in the form it claims they do. Vendor relationships lapse and the row survives them. Systems get decommissioned and the row survives that too. The record persists not because it is accurate but because it is inherited, and inheriting a document is a different act from understanding it.

The Hidden GRC Risk in Every M&A Deal: What Happens When Business Processes Collide

Not long ago, a CFO at one of the world's largest pharmaceutical companies said something that has stayed with me. We were discussing a major acquisition his company had just completed, and I asked what kept him up at night during the integration. His answer was not about valuation, synergies, or headcount. It was about business processes.